A misconfiguration at Universa Insurance exposed customer data to OpenAI’s crawler, highlighting the need for proactive monitoring of uncontrolled AI data collection processes.
Machine identities are a preferred attack target because they are often underprotected; structured inventory management, rotation, and monitoring significantly reduce risk.
Shared DeepSeek chats are indexed by Google without user warning, enabling third-party access to confidential content such as business reports and source code.
AI optimizes existing attack vectors such as phishing and credential abuse, while ransomware campaigns simultaneously employ data theft and multi-layered extortion – human judgment remains the primary attack surface.
SAP patches three critical vulnerabilities in NetWeaver, Approuter, and Commerce Cloud that enable memory corruption, unauthorized data access, and unauthorized logins.
Service Principals in cloud environments are a growing attack target because they are monitored less frequently and specialized secret-scanning tools like TruffleHog can automatically discover and validate exposed credentials.